Логотип exploitDog
bind:CVE-2021-42077
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-42077

Количество 2

Количество 2

nvd логотип

CVE-2021-42077

больше 4 лет назад

PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-7jgw-jw8c-v49c

больше 3 лет назад

PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-42077

PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-7jgw-jw8c-v49c

PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу